my neighborhood here (excelsior district) is more or less like a more packed in version of where i grew up (south oak park). Comparing living anywhere in SF to living in Lanwdale or Englewood is absolutely wild, outside of some very isolated neighborhoods.
it's not "just to get that data", it's to confirm level of access, check for potential other exploiters or security software, identify the machine you have access to, identify what the machine has network connectivity to, etc. The attacker then maintains the c2 channel and can then perform their actual objective with the help of the data they have obtained.
interesting that the most balanced one is extremely similar to the default, which is not so:
> \#198 (\texttt{QNBRKBNR})is the most balanced, with both evaluation and asymmetry near zero... Remarkably, the classical starting position-despite centuries of cultural selection-lies far from the most balanced configuration.
Completely agree- the coverage of MUNI + BART is actually pretty good (with some notable exceptions) and in my experience (ymmv obviously) less stressful than driving and seeking parking.
I'd put it in the zero-trust category if the server (or owner of the server, etc) is the issuer of the client certificate and the client uses that certificate to authenticate itself, but I'll admit this is a pedantic point that adds nothing of substance. The idea being that you trust your issuance of the certificate and the various things that can be asserted based on how it was issued (stored in TPM, etc), rather than any parameter that could be controlled by the remote party.